CVE-2026-1124
published 2026-01-18CVE-2026-1124: A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report.jsp of…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.46%
37.1th percentile
A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| yonyou | ksoa | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
ghsa·2026-08-25
CVE-2026-55619 [MEDIUM] CWE-1124 eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
### Summary
`eml_parser` uses the `email.utils.getaddresses()` function from the CPython standard library to parse e-mail headers that contain e-mail addresses (such as `To`, `Cc`, `Bcc`, `From`, `Reply-To`, `Sender`, ...). When the input header contains a deeply nested CFWS (comment / folding white space) construct, the recursive descent parser in the standard library exhausts the call stack. The resulting `RecursionError` is not caught by `eml_parser`, so the exception propagates and aborts parsing of the whole message.
### Impact
SOC pipelines use `eml_parser` to process untrusted e-mails. An attacker can easily create an eml file that will trigger the `RecursionError` during parsing.
The impact is mitigated
GHSA
GHSA-7v6v-gxc3-52qv: A security flaw has been discovered in Yonyou KSOA 9
ghsa_unreviewed·2026-01-18
CVE-2026-1124 [MEDIUM] CWE-74 GHSA-7v6v-gxc3-52qv: A security flaw has been discovered in Yonyou KSOA 9
A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
No detection rules found.
No public exploits indexed.
2026-01-18
Published